7 ms·
NAT is not security. [1] Why would you want to do NAT in IPv6? You can do all the things you mentioned with IPv6 without NAT. 1. https://samy.pl/slipstream/ h
by 0xbeefbeefbeef 5y ago
NAT is not security. [1]
Why would you want to do NAT in IPv6? You can do all the things you mentioned with IPv6 without NAT.
1. https://samy.pl/slipstream/ https://samy.pl/slipstream/
- yardstick 5y agoI never said NAT was security. No, the things I mentioned cannot be done easily with IPv6. You cannot easily switch a router from using one WAN to another (with different IPs) without requiring IPv6 clients having to obtain new addresses via SLAAC (and hence downtime), or use NAT (which is what IPv4 does, but not well supported in IPv6). You cannot easily have 2-3 levels of networks where router3 is attached to the lan of router2 which is attached to the lan of router1, which has internet access. This is because DHCP-PD is not well supported (see Comcast) or the prefix delegated is insufficiently sized (a /56 minimum should be standard but some will give a /60 or worse, just a /64!). This is bread and butter to do in IPv4.
- admax88qqq 5y ago> You cannot easily switch a router from using one WAN to another. You cannot easily do that with NAT either. Every single one of your TCP sessions will die, and likely every session going over UDP as well. Unless you're talking some special protocol specifically designed to handle clients changing IPs. Your machine may not notice, but the machines responding to your packets sure will.
- yardstick 5y agoYes you can if you are using a SD-WAN solution running on top of those WANs.
- anthropodie 5y agoIsn't it possible to have IPs from both WANs assigned to devices on your network? In that case you don't even have to switch.
- kaliszad 5y agoProblem is, the device doesn't have to know, which address is the working one - e.g. which prefix is working on the upstream. It might break connections etc. A solution of course could be to have NAT66 and I really mean address translation not masquerading/ port translation here - as such, much easier to do as it is a 1:1 mapping or to get provider independent space or become a LIR and have two providers announce your space with respective BGP configuration for failover. It is a solvable problem but isn't much guidance and experience with this at smaller companies that might not want to run BGP or go through hoops to get PI space etc.
- yardstick 5y agoExactly this. And you are right BGP is a non-starter for smaller sites, especially where cellular is involved. Often small site businesses just need a backup internet connection to access the web and emails, which doesn’t need the overhead of BGP. Also there is a non-trivial cost to using BGP (equipment, expertise, and ISP will charge more for the privilege) which for smaller business doesn’t make economic sense.
- dijit 5y agoYou sound like you know what you're talking about, which makes me a bit confused because you appear to be misinformed here. Your router will advertise new routes immediately when it's given a new WAN address, there's no downtime incurred explicitly from IPv6 in that scenario: local connections will still route until the timeout anyway. SLAAC issues (and can issue) more than a single IP per device, leading to interesting bugs like the ones Sam Bowne talks about in windows.[0] Changing a WAN interface _does_ incur downtime on ipv4 too, unless you're assigning virtual NICs and then failing over: which IPv6 would support in identical ways. [0]: https://youtu.be/YOglp0m35D8?t=1362 https://youtu.be/YOglp0m35D8?t=1362
- yardstick 5y agoYes sorry I should have been clearer, it’s the connections from clients having to timeout and re-establish upon IP change that is the issue. Specifically where those packets might be going over a SD-WAN type solution where a WAN change is non-disruptive to SD-WAN destine traffic. It relies on clients having NAT addresses and using those addresses for Internet destination addresses (not just private space). Another issue with SLAAC/lack of NAT on the LAN clients is you can’t do policy based routing on the router, eg I’ve got a fast fibre but it’s costly to use, I’ve also got a cheap and cheerful cable/DSL line that I use for backups and FTP. I want to route all requests to my backup service (which has a domain that resolves to a public IPv6 address) via the cable/DSL and everything else via Fibre. Easy to do on IPv4.
- dijit 5y agoBut, nothing you said is inherent to NAT, you should read up a bit more on iBPF for the latter and the former works exactly the same way on v6 as v4. Static routing is not really a thing unless you’re a really bad network admin- for sure your ISP wont be doing static routing to your home.
- yardstick 5y agoCan you talk about this some more? Also do you mean eBPF or iBPF or iBGP? If it's BGP that's just too complicated/expensive for a lot of the small businesses I deal with.
- whoknowswhat11 5y agoFinally someone who get's it. First - you can't actually get static IPv6 despite the claims that there is plenty of it as a home user in the US. This static IPv6 for everyone is basically a total lie. It's super simple with IPv4 to setup an internal network with known hosts / DHCP lease reservations if needed / dns etc, and have all that stay totally unchanged as the WAN link bounces around. If you are supporting a bunch of users (who yes, will configure a printer using the printers IP etc) then this makes like simple. You can do this at home too easily etc. There is a weird myopia in the IPv6 world about use cases for IP. It's like they just ignored what people need and want, and went a totally different direction. We need IPv4+ with another octet and be done with this :) I'm serious, anyone interested in trying to push this. Keep everything the same except with another octet at the front?
- BenjiWiebe 5y agoFor your local DNS names, etc, you could use the link-local IPv6 address.
- whoknowswhat11 5y agoFor some reason these change endlessly on my network. RFC4941 or similar privacy extension stuff might explain this.
- p1mrx 5y agoLet's keep the IPv4 header, but start counting packets from byte -2 instead of 0.
- bandie91 5y agoi need ipv6 nat because isp gives me only 1 ip.